CVE Database
/

CVE-2018-2434

Back to search

CVE-2018-2434

Published: Jul 10, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User Interface Technology (SAP_UI 7.4, 7.5, 7.51, 7.52). There is little impact as it is not possible to embed active contents such as JavaScript or hyperlinks.

VendorProductVersions

SAP

SAP NetWeaver (UI_Infra)

affected
= 1.0

SAP

SAP UI Implementation for Decoupled Innovations (UI_700)

affected
= 2.0

SAP

SAP NetWeaver

affected
= 7.0

SAP

SAP User Interface Technology (SAP_UI)

affected
= 7.4
affected
= 7.5
affected
= 7.51
affected
= 7.52

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now